Skip to main content

Vendor archive

pidgin CVEs

Beta · best-effort

91 CVEs tagged to vendor pidgin8 Critical, 13 High, 65 Medium, 5 Low, 0 Unrated.

CVE-2019-25544

Published Mar 21, 2026

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creat…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26491

Published Jun 2, 2022

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1257

Published Nov 20, 2019

Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2379

Published Mar 29, 2017

The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3698

Published Oct 29, 2014

The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sensitive information from proces…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3697

Published Oct 29, 2014

Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows allows remote attackers to write to arbitrary files via a dr…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3696

Published Oct 29, 2014

nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a crafted server…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 91 CVEsPage 1 of 4